Executive brief
Windows Biometric Service is a system component that manages fingerprint and other biometric authentication data. A heap buffer overflow vulnerability allows an authenticated local user to crash the service or execute arbitrary code with elevated privileges, potentially leading to full system compromise.
Technical details
A heap-based buffer overflow exists in the Windows Biometric Service, allowing an authorized local attacker to trigger a memory corruption condition. The vulnerability requires local access and prior authentication. Successful exploitation allows an attacker to execute arbitrary code in the context of the privileged service, achieving local privilege escalation. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows Biometric Service
Timeline
- 2026-09-08: disclosed